PT-2025-23473 · Netcomm · Netcom Ntc 6200+1

Quentin Kaiser

·

Published

2025-06-02

·

Updated

2025-07-08

·

CVE-2025-4010

CVSS v4.0

8.6

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Netcom NTC 6200 and NWL 222 series (affected versions not specified)
Description The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web interface are vulnerable to arbitrary command injection and use insecure hardcoded passwords. Remote authenticated attackers can gain arbitrary code execution with elevated privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-4010

Affected Products

Nwl 222
Netcom Ntc 6200